Konica Minolta bizhub C3350 bizhub C3850/C3350 Applied Functions User Guide - Page 37

Click [Edit] from [SA] on the [IPsec Settings] screen, then register the Security Association SA.

Page 37 highlights

1.5 Available operations in Administrator mode 1 3 Click [Edit] from [SA] on the [IPsec Settings] screen, then register the Security Association (SA). % Up to 10 groups can be registered for the [SA]. Item [Name] [Encapsulation Mode] [Security Protocol] [Key Exchange Method] [Tunnel End Point] [IKE Settings] [Authentication Method] [Replay Detection] [ESN] [ESP Encryption Algorithm] [ESP Authentication Algorithm] [AH Authentication Algorithm] [Perfect Forward Secrecy] [Diffie-Hellman Group] [Lifetime After Establishing SA] [Manual Key Settings] [Encryption Algorithm] [Authentication Algorithm] [SA Index] [Common Key Encryption] [Common Key Authentication] Description Enter the SA name (using up to 10 characters). Select an IPsec operation mode. [Transport] is specified by default. Select a security protocol. [AH] is specified by default. Select the key replacement method to securely create a common key used to encrypt communications. [IKEv1] is specified by default. Enter the IP address of the peer's IPsec gateway. This is required when [Tunnel] is selected in [Encapsulation Mode]. Configure IKE settings used for this SA. This is required when [IKEv1] or [IKEv2] is selected in [Key Exchange Method]. Select an authentication method. [Pre-Shared Key] is specified by default. Select whether or not to protect from replay attacks. [Disable] is specified by default. If you select [Enable] for [Replay Detection], select whether or not to apply extended sequence numbering for IPsec communication. [Disable] is specified by default. If you select [ESP] for [Security Protocol], configure the ESP encryption algorithm. If you select [ESP] for [Security Protocol], configure the ESP authentication algorithm. If you select [AH] for [Security Protocol], configure the AH authentication algorithm. Select this check box if you wish to increase the IKE strength. Selecting this check box increases the time spent for communication. Select the Diffie-Hellman group. [Group 2] is specified by default. Enter the lifetime of a common key used to encrypt communications. [3600] sec. is specified by default. When using a device that does not support automatic key exchange using IKE, configure each parameter manually. This is required when [Manual Key] is selected in [Key Exchange Method]. If you select [ESP] for [Security Protocol], select the algorithm to be used for encryption. If you select [AES_CBC] for [Encryption Algorithm], specify the [Key Length]. Select the algorithm to be used for authentication. If you select [SHA2] for [Authentication Algorithm], specify the [Key Length]. Specify the SA Security Parameter Index to be added to the IPsec header. You can specify different security parameter indexes respectively for send and receive. Specify the common key used for encryption. You can specify different common keys respectively for send and receive. Specify the common key used for authentication. You can specify different common keys respectively for send and receive. [Applied Functions] 1-31

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148

1.5
Available operations in Administrator mode
1
[Applied Functions]
1-31
3
Click [Edit] from [SA] on the [IPsec Settings] screen, then register the Security Association (SA).
%
Up to 10 groups can be registered for the [SA].
Item
Description
[Name]
Enter the SA name (using up to 10 characters).
[Encapsulation Mode]
Select an IPsec operation mode.
[Transport] is specified by default.
[Security Protocol]
Select a security protocol.
[AH] is specified by default.
[Key Exchange Method]
Select the key replacement method to securely create a common key used to
encrypt communications.
[IKEv1] is specified by default.
[Tunnel End Point]
Enter the IP address of the peer's IPsec gateway.
This is required when [Tunnel] is selected in [Encapsulation Mode].
[IKE Settings]
Configure IKE settings used for this SA.
This is required when [IKEv1] or [IKEv2] is selected in [Key Exchange Method].
[Authentication
Method]
Select an authentication method.
[Pre-Shared Key] is specified by default.
[Replay Detection]
Select whether or not to protect from replay attacks.
[Disable] is specified by default.
[ESN]
If you select [Enable] for [Replay Detection], select whether or not to apply ex-
tended sequence numbering for IPsec communication.
[Disable] is specified by default.
[ESP Encryption Al-
gorithm]
If you select [ESP] for [Security Protocol], configure the ESP encryption algo-
rithm.
[ESP Authentication
Algorithm]
If you select [ESP] for [Security Protocol], configure the ESP authentication al-
gorithm.
[AH Authentication
Algorithm]
If you select [AH] for [Security Protocol], configure the AH authentication algo-
rithm.
[Perfect Forward
Secrecy]
Select this check box if you wish to increase the IKE strength.
Selecting this check box increases the time spent for communication.
[Diffie-Hellman
Group]
Select the Diffie-Hellman group.
[Group 2] is specified by default.
[Lifetime After Es-
tablishing SA]
Enter the lifetime of a common key used to encrypt communications.
[3600] sec. is specified by default.
[Manual Key Settings]
When using a device that does not support automatic key exchange using IKE,
configure each parameter manually.
This is required when [Manual Key] is selected in [Key Exchange Method].
[Encryption Algo-
rithm]
If you select [ESP] for [Security Protocol], select the algorithm to be used for
encryption.
If you select [AES_CBC] for [Encryption Algorithm], specify the [Key Length].
[Authentication Al-
gorithm]
Select the algorithm to be used for authentication.
If you select [SHA2] for [Authentication Algorithm], specify the [Key Length].
[SA Index]
Specify the SA Security Parameter Index to be added to the IPsec header.
You can specify different security parameter indexes respectively for send and
receive.
[Common Key En-
cryption]
Specify the common key used for encryption.
You can specify different common keys respectively for send and receive.
[Common Key Au-
thentication]
Specify the common key used for authentication.
You can specify different common keys respectively for send and receive.